monitor-memory
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The
SKILL.mdfile contains 'Non-Negotiable' instructions for autonomous operation, explicitly commanding the agent to 'NEVER stop' and stating that waiting for human status checks is 'UNACCEPTABLE'. This attempts to override the agent's standard safety and operational protocols regarding human-in-the-loop control. - [REMOTE_CODE_EXECUTION]: Probes P08 and P09 in
probes/tier4_projects.pyread project paths from~/.agent_skills_targetsand execute code within those directories usingpython3and shell scripts. This allows for arbitrary code execution if an attacker can modify the targets file. - [COMMAND_EXECUTION]: The skill makes extensive use of the
subprocessmodule across multiple files (e.g.,probes/tier1_autofix.py,probes/tier2_persona.py,probes/tier3_smoke.py) to execute external binaries and other agent skills. - [COMMAND_EXECUTION]: The P04 probe in
probes/tier1_data.pyusesimportlibto dynamically load and execute Python code from a computed filesystem path (.pi/skills/taxonomy/taxonomy.py). - [DATA_EXFILTRATION]: The P29 probe in
probes/tier1_local_memory.pyscans and reads sensitive local files from~/.claude/projects/*/memory/*.md, which may contain private agent context or user data, and synchronizes them to an ArangoDB instance. - [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface in probe P29 by ingesting untrusted markdown files from the local filesystem and upserting them as 'lessons' into the memory database without sanitization.
Audit Metadata